Poco RAT is a remote access trojan used in campaigns against Spanish-speaking organizations in Latin America, including the mining sector. Activity distributing the malware has been attributed to Dark Caracal, also known as Darkling APT, an espionage-focused threat actor. Documented campaigns use phishing emails with malicious PDF attachments that direct recipients to download intermediate files from file-sharing services; those files execute droppers that install Poco RAT. The malware provides remote control of compromised endpoints, supports command execution, and collects system information. Dark Caracal has also distributed Poco RAT through financial-themed phishing as part of cyber-espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new campaign distributing Poco RAT to Spanish-speaking users in Latin America has been reported in the wild.
A new campaign distributing Poco RAT to Spanish-speaking users in Latin America has been reported in the wild.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan mentioned only as the predecessor of AsioGate.
A remote access trojan delivered through financial-themed phishing in cyber espionage activity.
Remote access trojan with espionage features (e.g., file upload, screenshots) used by Dark Caracal against Spanish-speaking enterprises in Latin America.
Remote Access Trojan (RAT) used by Dark Caracal for espionage, often delivered via phishing and fileless techniques.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.